Critical: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution
microsoft.com
microsoft.com
The IP Timestamp Option is more likely --- it's crazy complicated (among other things, you can play tricks with IP timestamps to determine whether two IP addresses are virtually hosted on the same machine). The good news about IP Timestamps is your router probably doesn't pass packets that have that option set.
First, I haven't had any email from Microsoft about this -- and for all that Microsoft has a reputation for being bad at security and not supporting open source software, they do take their responsibilities seriously when it comes to inter-vendor coordination.
Second, the details I've seen relating to this suggest that it relates to connection hashing -- which is relatively new, and thus is unlikely to involve code from the BSD stack which Microsoft imported so many years ago.
scrub in all reassemble tcp
MS fixed a critical bug. Yay. Why complain? Its better than Apple ignoring security bugs for years :)